MGASA-2015-0157
Dashboard / Vulnerabilities / MGASA-2015-0157
Summary: Updated python-dulwich packages fix security vulnerabilities
Details: Updated python-dulwich package fixes security vulnerabilities: It was discovered that Dulwich allows writing to files under .git/ when checking out working trees. This could lead to the execution of arbitrary code with the privileges of the user running an application based on Dulwich (CVE-2014-9706). Ivan Fratric of the Google Security Team has found a buffer overflow in the C implementation of the apply_delta() function, used when accessing Git objects in pack files. An attacker could take advantage of this flaw to cause the execution of arbitrary code with the privileges of the user running a Git server or client based on Dulwich (CVE-2015-0838). The python-dulwich package has been updated to version 0.10.0, fixing these issues and other bugs.
References: https://advisories.mageia.org/MGASA-2015-0157.html, https://bugs.mageia.org/show_bug.cgi?id=15558, https://www.debian.org/security/2015/dsa-3206, https://git.samba.org/?p=jelmer/dulwich.git;a=blob;f=NEWS;h=d0616a0c
Affected packages
Package
Name: python-dulwich
Purl: pkg:rpm/mageia/python-dulwich?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
